#general
1 messages · Page 895 of 1
Bummer
Your processor has a certain number of virtual cores. Usually 16, 32, or 64 these days. If we were dealing with a task which did not require any I/O or dependencies then there would be no point in opening more threads than you have processors, or you'd be wasting a lot of time switching between them.
As it stands we are dealing with network connections, which obviously have latency. The optimal number of threads is therefore just a bit higher than your total number of available cores. The exact amount higher depends on how much latency, what else you're running, etc, etc, etc.
So a million threads would actually be pretty inefficient, but using a processor with 64 virtual cores, 70 or 80 might be reasonably effective, context dependent.
If you were after maximum efficiency then you'd benchmark it. As it is, you probably don't care that much, so just pick a number in that range and it'll be fine 
What a nerd
I’m going to benchmark 1 million
Also worth remembering to take the target into account though. You don't want to risk overloading the server
Meh, it’s a THM server tho 😆
On one hand, AWS get pretty annoyed if you mess with their network infrastructure...
On the other hand, that's THM's problem to deal with 
the path stoped in the careers and jobs of cybersecurity
Scroll down and theres 3 more avenues
SOC analyst, Pen testing, and security engineer
Thanks Krusty
Gave +1 Rep to @lusty tusk (current: #1765 - 2)
Hey friend. Thank you for my first rep 🙂
Second actually
No problem :) enjoy
there isnt
https://tryhackme.com/hacktivities is the link
thank you
Gave +1 Rep to @lusty tusk (current: #1329 - 3)
Quick question for y'all. I want to setup my own home lab to get practice with SIEM tools as well as some pen testing. I can obviously look up a guide for this, but I just wanted to see if anyone had any resources they really liked, or guides they enjoyed following.
👋
how are you?
Busy with many new exciting projects. 😎 How about yourself?
I bet big announcement tomorrow 🙂
I'm eating dinner
Massive one for TryHackMe. 🙂
The SOC analyst cert?
I use wazuh via a VM which is good. Just setup your agents on each computer. you can combine other tools like wireshark and suricata too. I like to have suricata as my IPS and wireshark to feed my suricata etc
Thank you!
Gave +1 Rep to @drowsy dust (current: #168 - 49)
Wonderful steak and barolo? 😄
not tonight, 0 effort because I'm a bit sick so just a schnitzel 😂
Another question for you! How do you document what you do on it? Like obviously having it setup means a lot, but how do you use it personally?
From Vienna I hope, Wiener schnitzel. 🥳
If that question doesn't have the best clarity, let me know 😂
argentine version 😂
too much to explain really. but to link them together it just takes configuration of everything
I mean more like, once everything is setup, what do you do to learn from it?
Like do you test out new pentesting techniques you've learned?
Ah. Maybe you could learn by attacking your machine and seeing what triggers it and what you need to add to make those triggers go off
Milanesas a la Messi 😄
ankara Messi
i.e you could see if nmap triggers it
if not then make it so it gets triggered
etc
milanesa de pollo 😂
and yes that would be a good way to mess around and consolidate the information you learned. along with learning the blue team side by seeing if your SOC picks up anything and why
you can tweak both your attacking and defense by doing that. i.e maybe doing a stealth scan gets past your SOC then you can set up your soc to pick up that next time. and then try another way your SOC doesnt pick up
etc
That makes a lot of sense! Thank you! Is that mainly what you do with yours?
Gave +1 Rep to @drowsy dust (current: #160 - 50)
At the start thats what I did to harden my system more. But I mainly have it as a protection
that and my pfsense
So you have it setup on your actual network, not just in a simulated environment?
I have wazuh in a VM but it still works the same
and yeah its to protect my endpoints
pfsense is my firewall into my whole network
Ugh! Keyboard oil all over my keyboard 😩
Why’d you say it like that
That's really sick. Thank you. I'm like 6 months into my journey in this and it can be a lot to wrap your head around.
Gave +1 Rep to @drowsy dust (current: #157 - 51)
I’m just excited
Def, just keep learning. You got this bro. Cyber is a life long learning career
you're making it worse
Oh yea?
yeah
why he look like curious george
I like it though
ok diddler
0 Meng Hao 679
1 Li Qiye 6340
2 Wang 234000```
Hiiiii
Hi dictective
Because I’m oiling my keys?
Paul Erdos used to religiously take amphetamine
What
You can oil your keyboard?
I thought fast food grease and crumbs was enough for most gamers?
I believe in you uwu
this meme put fetty wap into my top 10
how do i join the JR Penetration Tester channel
#junior-pentester-path <- click here
Thanks Jabba
Always 😎
Yeah, baby.
Ay, I want you to be
mine again, baby, ay.
I know my lifestyle is
driving you crazy, ay.
I can never see myself without you,
we call them fans, though,
girl, you know what we do.
I go out of my way to please you,
I go out of my way to see you.
done, finally done
Glock in my rari
https://discord.gg/gNwUMzc9Dq
Check out my dogs channel: BearTheBulldog
hello
No. Contact email providers support.
L server

(He left already)
Fucker said "L Server" without doing basic googling for "TryHackMe"
Hi guys I'm doing master's in computer application i want to start my journey into cyber security can anyone guide or give me a roadmap
“I am become meme”
If you in software apps you may follow the security devs path
W server
Crazy right , people find easier to come to a rondom discord server tryhackme then googling questions , how weird
Lmao
Will there ever be an ethical hacker path?
Or is that basically pentester
Yes
Okay
Basically that
Okay thought they were two different roles
Honestly, ethical hacker is just hacking but ethically 😂
True
Hello anyone here know anything about aws buckets?
No sorry
whaaat no way
Jabba probably would but he’s not online
Crazy right
A little bit
when is thm going to add an unethical hacker path 😈

all the wannabe instagram hackers here will finally have resources
someone here asked about snapchat lately
didn't know ppl still use snapchat in the year of our lord 2025
i thoutght that shit died in 2016
ah im doing bugbounty atm found a aws bucket that i was able to curl upload a .txt to. just not sure what kind of vulnerability this is even if it is at all. from what i understand if i can download/ upload i can read/write and change data or put malicious things on there right?
i believe it should be 403 at least
Task 1: Don't be unethical
Task 2 : Surrender yourself to the police
Sup Ya'll!
Oof, yeah don't be unethical we got enough threat actors in the world as it is.
Broken access control, P3 severity.
or P1 if its a public facing asset, normally
Honeypot for the FBI
jks jks
appreciate it👍
Threat actors right now
congrats on finding it!
yeah for real, good job @cold sparrow
bro youre on a roll
enjoy your bug bounty $$$, spend it on something cool like pentesterlab pro for me 
haha Thanks, the real problem now is writing the report lmao
'yeah so there's like a vulnerability on your website and i hacked the shit out of it'
Templates are great for this.
Has anyone used the github workflows before?
Hackerone has somewhat of a template to follow gladly
yeah ive been wanting to go on there more. havent found much on h1 maybe i would on bc
Hey guys, just starting my journey super excited!
good luck
thanks!
Good luck on your journey 🙂 🚀
How long have you guys been doing it for?
i read a bunch of books a long time ago but i didn't know there were websites with labs like this that you could use to actually use the information and i forgot most of it but i just signed up for this this week lol
i didn't want to create my own lab because it seemed like you would already know what the vulnerabilites are and that would be boring lol
I am on introduction to Lan, i feel like i am going to forget alot of the information do you take any notes?
so about a week but most of this stuff sounds familiar lol
yeah i should have from the beginning but i just got obsdian installed
too bad i dont' know markdown lol
Yes, you should be taking notes
I can imagine reading books cant even compare to this type of learning though.
Thanks guys will do that and save myself the stress of trying to remember/research stuff.
i learn better by doing so i think this will be better
i still think books would have a ton of information that it would be hard to get in this format though
anyway
like the web application hacker's handbook is one i read and that had a ton of information
there is one about bug bounties i want to get
bug bouty bootcamp
might be some overlap though
Action Jack Barker
Just finished a room on PowerShell me no likey, necessary evil, powerful and good stuff, just gross after learning linux so well haha
i was gonna use media wiki for notes since i can easily install it on my server which has to be windows and access it from any device, but obsidian has files that i think would be more usable with some other editor if i get tired of it
yeah the thing i dont' like about powershell is how incredibly long even the simplest scripts are
compared to bash
its annoyhing
it seems overengineered
Exactly the vibes I got from it
Like executing one command on a remote computer is crazy
Lots of typing, on the bright side once you know how to invoke a script you can save anything you spent a lot of time engineering and then you don't have to repeat it haha.
My, "the glass is half full" version of PowerShell lol
it just seems everything to do with windows is way overengineered and over complicated
there are probably exceptions but it seems that way
I enjoy it because its complicated
So far at least
I've only done the basicest of shit with windows but the organization of it fascinates me
It is indeed clunky compared to linux
Do you have some examples?
Time on keyboard also makes a difference when it comes to perceived clunkiness
i just mean that with windows it's usually harder to tell exactly what its doing
how are you?
i dont' know why i can't think of a good example atm lol
Chilling hbu
i think the registry is kind of labyrinthine and unintuitive and i don't know why they had to create their own proprietary database just for settings then provide the most unusable tool to interact with it. I know there are better registry editors but i don't think you should have to rely on non native tools just to interact with a core feature where with linux everything is text so any editor works
I think putting each program and all the files associated with it in their own folder was a mistake too because it leads to absurdly long path variables.
you can't really add all of your softwar to the path because there are too many paths
i do kind of like how groups and permissions work though lol
seems more flexible than on linux
anyway ill stop since i dont' think anyone is reading this lol
I am
ah ok
As am I
Will a VPN let us try gpt operator on a pro sub or ban
If you're directly editing the registry, I have some questions. Have you considered using local GPOs? I guess my question is why are you editing the registry directly?
Why would you not put a program and it's files in the same place?
its actually been a while since it did, but what if i just wanted to add something to a shell menu or something
and a lot of software doesnt' clean up its registry keys
Confused here too
because if you want to run it without typing out the full path hyou have to add it to the path variable
if all your binaries are in one of a few folders you have a short path variable
df = pd.Dataframe(data)
df.to_csv(“data.csv”)
if they are each in their own folder you have to add every path and you hit the size limit of the path variable
its inconvenient
What are you doing/using where you have to add every path manually?
I'm trying to understand how you're using window, because it's not making sense in my head
it seems that a lot of windows versions of things don't add their path to the variable
To what variable
like eclipse
Lol
to %PATH%
so that if you just type eclipse it comes up
windows does have a search feature now
So you're just using CMD to do everything?
but it seems overwrought to have everything in it's own folder and not on the path so that you have to actually index and search things instead of just going directly to it
it seems it doesnt' bother me most of the time but at times if i am learning a programming language or something it becomes a pain
it depends on what im doing
From what you've said, it seems to me you're adding in unnecessary complexities. Just what I am thinking trying to follow along
actually fuck it works just pass isn’t working
Probably not. If you need assistance with a room, #room-help
is the password broken
I'm not sure what you mean
Isn't it only available in the US currently?
if we're not in the US would a vpn let us try operator
Do any of you guys have compiled bash scripts for like searching for flags, or setting up defensive anything on CTF competitions etc?
I would follow THMs TOS
Talking about GPT not THM
or you mean coz unethical
if so makes sense and my bad just wondering
Personally, I love following TOS 😄
i think most companies know if you are using a vpn ip anyway
US residential proxy*
why not pipe the output of where into your command so you don't need to type it yourself?
I'll ask gpt if it's allowed
If it's region locked, the answer is no
why is this password not working
I just find the design of linux more pleasant
not my first time ssh into thm i’m literally not doing anything wrong
Im surpirsed you dont' find it annoying to use command line tools in windows though
Linux is absolutely beautiful
Unless the room specifically tells you to ssh, it's probably not going to work.
and the tab completion is anoying
Has anyone tried the AWS Cloud Training ?
i think it is the design is just simple and kind of poetic or somthinng lol
If you're talking to me, I use both equally, without issue or preference tbh.
Yeah
it’s telling me to
What is your experiense ?
I use both but i have a preference
Are you in the attackbox or your own VM?
nope on theirs
Is it Begginers Friently ?
the issue is when i enter password
Did you start the box in the room?
It’s pretty boring but informative. It should give you a good chance of getting the AWS cloud certification
It is imo
Yeah very
OK, #room-help
I am trying to get into cloud Security do you think thats a good start?
Yes, I can’t think of a better place to start
Have you finished the whole thing?
it worked
the credentials weren’t the normal ones….
After 1 hour && about 16mins I finally finished installing Arch Linux.
condolences
Yeah man, I use Arch btw.
Lfg
Congratulations! Now do it all over again
first linux distro i ever tried was gentoo. I picked it basically at random and i thought that all linux distros were like that lol
Nope. I’ve put it on hold
my first was parrot i think
LOL
Mine was ParrotOS && I had it for a year because I was trying to dual boot it without knowing what I was doing and I couldnt install windows back
Oh I also know Red Hat
oops
i took that exam and failed it lol
red hat
I can say it feels way better than Parrot
Uptime: 7 hours
4 of which were installation
For some time I couldnt connect to wifi either
I used to want a distro where i could customize every single aspect but now i just want it to work reliably
Missing dependencies
i dont know what i want so i always go default
yeah i had to restart from my USB like 3 times because i did the wrong thing
And then I used the wrong keyboard layout somehow
LOL
Ah yes, a classic
Lmfao
38 mins in hes still not done
Nop
it took me two different nights to install gentoo but i had to let it compile overnight
i took notes
lol
but it was the first time i used linux
whew it is not 2007 anymore, please do away with your non-blurred transparency
wow man
idk i just like the transparent
just like use your eyes and determine the readability of the terminal screenshot you have posted lol
I only half kid though
that was my only pc too and i decided to just get rid of windows so i had no pc till i got it right
if you like transparency, you just need to make it more opaque so it’s actually usable
lol
eyesight != readability
im the one reading it 😄
True, so you’re just giving yourself a hard time for no good reason
Your screen shots are now banned /s
lol
Audiobooks 
Anyways I don’t care all that much, juts thought it was funny. Been a while since I saw a term that was so transparent
i find it quite readable imo however I wouldn't do this myself
Layers are old school. Modern times we just sandwich everything together
https://youtu.be/j_I9nkpovCQ
Your next assignment
Did you know you can run Linux on an M1 Macbook Pro? It’s now possible thanks to a new distro called Asahi Linux. I did some investigative computing and was able to run Arch on a brand new Apple Silicon M1 pro chip, but with some caveats…
#mac #linux #TheCodeReport
🔗 Resources
- Asahi Alpha Release https://asahilinux.org/2022/03/asahi-linux-a...
I can't tell the difference tbh
Personally, I would change the font to FiraCode
gotta change the color to match your THM level color though
I mean there’s an entire distro for that… before lol they switched to Fedora
Not exactly a difficult assignment

Just limiting despite how far Asahi Linux has come
Btw
@sinful moon o/
Heya!
Now I’m salty since I can’t play my MMO until 5am due to scheduled maintenance. Rip
pretty sure companies schedule maintenance only when they know i'm gonna need to do something
I need a break
Yeah literally the day after I beat the main quest of the 2.0 content and was excited to try flying around and more lol
Although it was big oof two weeks ago when there was downtime for the admin panel of our MFA solution when i was scheduled to onboard an end user with it
thankfully authentication still worked, we just couldn’t you know… administrate it lol
good thing authentication worked lol
Yeah I’ve never seen that go down, besides SMS and voice call methods which, shouldn’t be using those anyways
anyways it was nbd, I just called the user the next day and got them sorted
Alright chat is too quiet, Imma check into VC in another server and if that’s too boring, then just amuse one of my various obsessions after my plan for tonight has been ruined lol
Virtual machine 1 was annoying af
downtime with any auth has gotta be a shitshow ngl
Eh it just prevented me from bringing user out of Bypass so nothing was really impacted with this security onboarding I was doing with them on this new computer, just delayed
although lol I couldn’t send them the normal SMS invite texts for the MFA app/service either
good time to phish IT
lol we barely use the admin panel’s “lets send an MFA request to ensure the user is who they say they are” due to our relatively small scope. I know most everyone by name and the sound of their voice at this point, even with me working remotely
i'm waiting for the day "ai" voice spoofing becomes half viable
will be fun
Mhmm, still really only in the realm of “warn your elderly parents about it and set up a passphrase”… if that
We do technically have passphrases for use with our clients but I have never seen that actually used lolol
lucky for me about 30% of level 1 IT people I've met have the sense of those eldery parents
ouch lol
and yeah our clients, especially the handful of wealthy individuals we support, are more likely to fall for bs MS tech support scams than something more advanced actually trying to impersonate us.
That’s thankfully gotten better though as we’ve increased our awareness training, even if just mentioning how these scams work to them 1:1
They’re usually smart enough to call us instead of the fake number on their browser hijacked screen lol
i'd wager QR codes are probably still top tier
lol as if our users are smart enough to even fall for the QR code scams
they’d try to scan it with their MFA app as we have taught them which would result in… nothing
I know someone who fell for one of those. I don't know why she thought microsoft wanted payment in play store cards
speaking of qr codes, thank god restaraunts are finally stopping that crap
that was horrible
not even a security thing just horrible
thankfully never run into that but yeah it’s gross
I have had to remediate several of those real time. One scammer attempt had installed the same remote support software that we use, so I had to very carefully kill theirs without killing ours lol
no menus, you gotta scan a QR code they stuck to your table and browse their online menu with shit reception on a shit website
worst thing since microsoft
ohh that's annoying
I'm glad we can't remote into customer's computers
i dont' want to know what they have on their computers
True, but consider:
I have seen some very advanced coordinated financial scams though against one of former clients who operates a local franchise chain
what's a qr code scam
most qr codes
They had insider knowledge about how the property management system worked at this multinational chain and scammed many many locations out of significant sums of money by making “test” transactions which were anything but a “test”
but if you mean security wise, typically phishing
When it leads you to a malicious site
When it’s a rick roll instead of unlimited money
Probably
yeah they’ll use QR codes to get around anti-phishing software techniques
Truly malicious
cause a lot of people used to assume qr codes in certain places = safe
that too
would this fall into social engineering?
yes
It’s not any more advanced, it’s just “hiding the lead” so to speak
good way to put it tbh
The only time I’ve seen a user actually receive one that wasn’t blocked by our email security software they just straight up asked us what to do with the QR because they had no idea lol
lol
so I doubt the effectiveness unless you’re moderately “with it” tech wise and have grown to trust QR codes
oh the Mesh email security platform? Yeah I tried to steer us that way, but we went with another well respected vendor
which also happened to be on my shortlist of recommendations so I can’t complain
inky?
Nah. Guess it doesn’t matter me saying realistically, just taught to be cagey. We went with Avanan which was gobbled up by Checkpoint. Checkpoint I have mixed feelings about but their core Avanan email security platform is fantastic
I wouldn’t even know, we’re pure 365
They at least claim that they were amongst the first to really debut the API based model instead of hardware gateways around 2015ish
idk if it's still the case today but i think avanan was the one that required just a straight super admin acct for their "integration" with gsuite, rather than tying into any api or having limited perms
Ah gross, having glanced at those docs I don’t think that’s still the case, but yeah never something I’ve had to put into practice
in their defense i guess, working with google's api stuff fucking sucks
I was trying to go Mesh because MSP focus and also still had a gateway option when we still needed ours, but by the time we finally started shopping around, we were pure 365
now i might make a qr code rickroll and put it in a random bathroom
but yeah I’m significantly happy with the improvement in detection and etc compared to our old Barracuda Gateway
Make it a Fetty Wap roll
but yeah 365 wise mesh inky and avanan are all solid, i was impressed with mesh but can't complain about either of the bunch (again, except that gsuite integration showing a pretty bad security mindset)
I used to have to remediate client requests for 40+ spam/phishing attempts every two weeks, now it’s easily under 10 for two weeks
Self host it so you can see just how many people will follow it while faced with a poo and curiosity
thinking of Gateways, you may be interested to hear null that for personal use, I installed a Unifi Gateway Max in our home network and am extremely happy with it
also happened to take over network admin from my SO finally lol. Despite also working in IT, he himself admits he’s not a “networking person”
i've been iffy about unifi over the years but at this point i think their products are getting pretty mature
kinda want a few
Yeah they were no question for APs and switches but their gateways have gotten good enough they’re just replacing our firewalls at many client locations
i have an innovative idea
those aren't allowed here
i kinda want one of their switches just cause pretty lights
nah gotta drop something that'll do it randomly every few days
Plus I mean, finally a mobile app that’s not crap and lets you administrate 97% of everything you can in the controller
sounds ethical
impossible.
Yeah it’s actually kind of wild
or scp foundation
never thought I’d run into a OEM networking app that wasn’t crap
most companies can't even make their web ui not crap
if i didnt' know what it was that would be so weird to get from a qr code in a bathroom
the stories are just strange
mhmm but to be fair Ubiquity’s UI is kind of known for being fantastic
and yep, I’m just self hosting the Unifi Network Server on my… erm, server
you can get gateways with that feature integrated, but I rather like that being its own thing
aight time to knock out
to be clear, when the server is down, the devices continue to function as normal, it’s only needed for management and stats
will hopefully know tomorrow if i can actually accept this offer
alright see ya then! Nice chatting as always
if so, finally free
Not sure what this is but indeed, good luck!
🙂 👋 🍪
Ah very nice, should be great. Good luck indeed!
good luck to you!
I don't think i will ever get a job like that living in a rural area with no plans to move
but good luck
sorry
just use your human networking resources as much as you can for that chimera
there are no organizations big enough in like a 100 mile raius
Ip found : 192.168.0.1 consider everything hacked
Oof, got distracted waves goodbye to 40days
I’ve actually turned down two offers to work at a multinatioinal bank in DFIR/SOC since I was still getting tons of experience from my current job. But yeah when they’re hiring again I’m for sure going for it
lol there’s a reason I redacted my public IP from that image, I just made it the same color as the BG
Someone told me their ip ended in .822 and I just looked at them like -_-
lol
i don't knwo if i would want to work for an acutaly bank though I kinda like working for a company where the product is some kind of technology becuase the people abover you understand what you are doing
and tech companies tend to be more laid back usually i think
Anyways my point there was, I have a close friend who is DFIR manager at that company so that was just one of a couple avenues for career progression I have in mind
It’s still hit or miss
yeah no corporate, especially in finance, is a shitshow sometimes and has tons of red tape -- but $$
possible if they are using IPv6 addressing
Yeah meanwhile this is a major major corporate org so it would be a huge adjustment for me
It was an ipv4 😭
Tech companies have lots of pseudo or non tech people and that part can be mind numbing
the first place i worked after school was a smaller company and they put the cfo in charge of it for some reason
he had no idea what anything meant
but he didnt' want to spend money on anything
lol my managed service provider is so small that my boss is the CEO/owner/lead tech so…
If they see a terminal they think you’ve made a deal with Gandalf
yeah different vibes
They can be, except when you get into all of the small business issues lol
It’s a blessing and a curse
like what
Single user for all devices, password is company name ☠️
Informally I have like 6+ job roles, great experience, but wild to keep track of everything I practically do
oh yeah
Nah that’s why we’re a MSP, lol we do IT for all the companies who would be doing that sorta thing normally
the company i worked for had really obvious sql injection vulnerabilites in the internal software that the sales peopple used
'==1;
we call him little bobby drop tables
end of life servers
that can be a difficult fight to have as an MSP sadly lol
one person accidentally downloaded ransomware that encryped the big shared drive that every office in the whole company used
i wou;dnt' talk about it but that company is gone now
I think some people just say haha doxed you and say a random ip without even thinking about if it’s possible 
ouch, but also that shouldn’t be as possible due to permissions and more
Backups, v. important.
mhmm
fortunately there were backups
we have hourly backups of servers
she just shouldnt have been able to encrypt things she didn't have anything to do with
Yep, PoLP gets ignored all too frequently.
only ever had one client ransomwared… twice. It was before my time but both time it was due to the company refusing to accept our security standards, demanding everyone was admin with full access to shared folders and more, etc
‘ ==1 AND DROP Table
everyone gets the day off, forever
they were not a client for much longer lol
I have a few systems at work where I've asked for a Read account so I can better do reporting/root-cause analysis etc.
And end up with RW 😄
the person who was to blame was the same who demanded weakend security or else “they could not function” lol
hey guyz, what's up with that “certification” thingy they were gonna release today? i don't see anything new
Oh yea I wonder why they wouldn’t announce it at 4am
reminds me of peoople who refuse to reboot their servers cause they can't have downtime
for updates
lol no one is that important and if they are, they need correct failover/HA
well if you don't update them there could be a lot more downtime lol
we administrated a national transportation company and they were more than happy with our Friday evening maintaince
could be ill believe it when I see it!
good morning
yeah people who have been comprimised have a completely different opinion about updates
its hard to convince them beforehand though
🙂 when do you think its gonna be out?
meanwhile internal IT which took over for us has stopped patching or rebooting these same servers… Good luck to them!
basically they got bought out in a pump and dump move from a VC
An educated guess would be office hours. A conservative guess would be noon
so they only care about cost cutting to resell, and MSP looks like an expenditure
WHAT TIME IS IT IN THE UK?
yes
yeah fr
"I never have to call you why am I still paying you??"
moved our VMs from a dataceneter to… “the cloud” aka Microsoft’s datacenter and they’re going to be charged out the butt for those VMs… but hey “the cloud” is more marketable for selling the company lol
its almost 6am
😂
I think they appreciate yoiu more if things break once in a while and you can rescue them
The funny thing is they called us constantly with issues, but it was all minor stuff
Google: what time is it in the bloody Uk
i think its actually true
I know all of the actual boots on the ground employees miss us tons and compain
you look better when you are doing things wrong but can 'fix' it fast
Should be about 5am GMT right now.
that's what the guy who created the software with the sql injection was like
Not when the thing you do wrong is security!
They’re also big enough that I had the pleasure of preventing major threats like qbot and other big name initial access malware from fucking up their entire org
he was definately doing security wrong lol
usually the stage 1 loader would run but our EDR would catch stage two and I would more than remediate and do writeups
@sinful moon do you only do defence or are you also into red teaming?
My org is so small I do everything even tangentially related to “security”. However most of my offensive stuff is informal, as my firm does not meet the criteria for being certified for pentesting for PCI-DSS compliance and similar. Most often I do an initial test before we hire a qualified org
what kind of test
although some of the most fun I’ve had was testing our current EDR product to which our managed SOC called us in alarm a couple times that day lol
I mean I can’t say I’m a formal offsec professional but I know enough to cover our companies butt to make sure I can find concerns before we bring in a third party. Sure some of that is defensive and sometimes a bit of poking around
that sounds sooo interesting. was it anything good? was it a false positive?
interesting
when we’re the IT for dozens and dozens of companies we want to put on a good face that we didn’t at least overlook something obvious for our customers
yeah that makes complete sense. and ofc that little bit you do in the offensive side also compliments your defensive skills 😌
The EDR product is very good, I was able to do some things that slipped through but they were ironically very basic things compared to the advanced techniques I used which the EDR very much alerted us to
Can anybody here hack and destroy a roblox game
I need help urgently
I don't really have any hacking experience but I can here to seek help
@shell nova please see the above, thank you
Gave +1 Rep to @shell nova (current: #13 - 623)
lol accidental thanks
If they are doing somethign bad, report to roblox support and if it's bad enough, law enforcement.
They wont
I've reported them so many times
It would be illegal to hack and destroy a roblox game as a private citizen, regardless of the reason.
read rules
@sick lance nvm juun here
Please stay out of this.
interesting. yk i'm more interested in the offensive side, and I'm about to set up a lab for malware reverse engineering
I got well ig I'll keep searching
I just ask because I literally watched a kid get groomed
What’s everyone doing
And I really need to take this down because roblox admin isn't doing shit
Please don't. If it's not bad enough for law enforcement and doesn't violate the roblox TOS, hacking that roblox game could put you in the sights of law enforcement for cybercrime.
I understand
It does violate the TOS
But no body is doing anything about it
Have screen shots and everything
I think ima eat a whole can of tuna
inv me
I got banned from the said game with the explanation "for being a rat"
Then keep reporting them to roblox support. If it's against ToS, roblox can shut it down.
Alrighty
Keep outside drama outside, I am just telling you that what you want to do is illegal and I strongly recommend you do not take any action to damage or compromise that server or game.
Don’t overdo the tuna. Normally too much will lead to mercury poisoning
one whole can bad?
Hi, someone hacked my call of duty account but i don't know how and why
as I understand it you need to eat an excessive amount of Tuna for that to even be an issue
Nah that’s fine
You don’t need those enzymes anyways
Contact Activision support
Just don’t eat 10 cans or smth
true
dont listen to them. they dont understand true tuna love.
lmao
You don’t say
I’ve eaten way more than ten in my lifetime
is it possible to get back my account?
yes
Well I hope not in a day
We don’t know unless you contact the people who actually administrate the servers and your account, that would most likely be the publishers, Activision
Nah, just an hour


In all honesty, the best thing you can do is contact Activision support and go through account recovery processes.
Uggh
🤨
tuna time boys
Seriously, report to Law enforcement. They will kick it up the chain, and report them to roblox. I appreciate that you want to protect people, but complaining about it here isn't the way to go about it.
if that really is the case, the best that you can do is write an Email (or maybe a hundred) to Roblox.
with evidence
Do not collect evidence of wrongdoing. You can actually poison the case and ruin it.
I think the best is a police report…
Um yes? Why do you ask lol
to connect to my cloud vm bro
Then what do I collect?
The best thing to do is report to police, and with that I'm declaring this topic closed. Please move on to another.
Never heard of her
I can't connect
No more discussion of this hacking roblox nonsense.
lol that sounded fun I missed out
It’s literally just an IP and port 3389 unless there’s a RD gateway server which probably isn’t
i cant believe this aws section is like $350 omg
You probably need to work it out with the server admin
onesec I will send u the error
Used to love tuna till I had it every day for half a year
are you trying to connect from linux or windows
Given the context. Self collecting evidence is terrible advice
was not prepared that
lol excited for work flashbacks, alright
tuna
TUNA
Spinning up this AWS infra on the fly is extremely expensive. This used to be exclusive to business customers of THM. So them even offering you to pay out of pocket is actually a win
wait wtf is going on lmao
Nope, move on.
Damn. Just blasting that IP eh
Not sure why I leave the domain blank
No more discussion of that topic. Last warning before mutes get handed out.
domain is for if you are logging in with an active directory user
top level discord mod
That error doesn’t really say much lol. And you don’t need a domain unless it’s Active Directory authenticated
but chat gay bisexual and trand(chatgbt) said it is ok to leave domain empty
i am just wondering what i tabbed into when i opened discord
Juun bout to go oprah with those mutes
He/she wants some
ah ok so what do I do?
yes that’s just what I said although why does that chat have an RDP server lol
you wanna maybe reword that in a way that doesn't sound exclusionary and pejorative?
my tuna :((
I would advise removing this photo so other's don't get too curious about this IP address
Tf?
oh I misunderstood the badness
if you have access to your email still i would change the password to be safe
sure bro, I did but it is an empty vm anyway
in the cloud so i thought it is ok
better safe than sorry
Posting public IPs in a hacking discord is not a good idea
Not sure what u mean
someone is going to want to play silly buggers
My next troubleshooting steps would have been a port scan lol
telnet ip 3389
let them hack an empty just made cloud vm for testing nonsense i don't mind
if it's a VM can you not access it via the web browser?
Make sure to fan the smell out
…well if they can’t access it, surely no one can
But okay is this infra you operate or not? If not just work with the operator who probably knows more about the setup
why?
No they wanted me to download, but oH leet me try acually, ru familiar with cloud vms bro?
have you attempted using SSH to access the VM?
I have some familiarity with using cloud VMs, yes
So your cat gets more jealous
Hello, is this IT support? Yess I spilled tuna on my keyboard
ssh for linix no?
usually
nice bro, did u take any cloud certs?
i am doing az 900 rn
I have az 900
oh wow. how was the test?
lol thats cruel
I spent less than a week studying for it as I had some familiarity before deciding to take it. It was fairly straight forward.
im cuddlin my cat rn. he came into my living room and requested cuddle. he will now recive the pats
I run several cloud VMs both personally and professionally, just makes me sus as to why you’re having issues with a simple task such as this if you’re actually studying for these certs
Yes it is easy so far bro, but did the exam was so easy like no stupid questions to make u fail and make them earn extra or something?
lol like simple things, is 3389 actually open to the internet? Normally that’s pretty not great but who knows
My first cloud cert so
u had issue with it too
lol
Guess you'll find out once you take it
u can't troubleshoot it so 😂
nope!
lmao
ofc!, I meant i ur experienc
e
?
You’re just not answering any meaningful questions or explaining reasoning. So is 3389 just raw dog open on this, and who’s infra is it, yours or?
Shodan go brrr
I've found lots of 3389's open, but all of them were Chinese stuff, so.... 
yo gang,
I need your opinion... would reverse engineering and malware analysis make me a better red teamer???? I really just wanna get into the top 50 in the world!!
lol that’s improved then, US and Germany are often the worst offenders for MS protocols
infra? idk tbh let's hope on a voice call?
Yeah its mostly just Asian countries from what I see
Infrastructure
I can share my screen thee
Germany does have some exposed protocols though
it is windows server
lol while I am tempted it’s usually best to keep this in chat
why? don
t be shy
lol
yes, but hosted at AWS? DigitalOcean? Another vendor? Do your cloud networking setting even expose that port? etc
ok no malware right?
jk
Yeah I guess I should strike DigitialOcean from the above, they don’t technically support Windows Server although you still can
the port is probably closed like @sinful moon keeps saying
Digital ocean?
I'm assuming they are using Azure as they are studying for the AZ 900
hosting company
DigitalOcean is another cloud hosting vendor like AWS and Azure
az 900
then sure just use their guide above lol
ah not popular, btw do u have a cloud background or certs?
DigitalOcean is quite popular
I have a cloud and infosec background, no certs, just self taught for over 20 years
and yeah it’s probably the biggest out of the main three AWS, Azure, GCP
or one of the
oh I heard google cl, azure and aws are like the main players
nice, but why no certs?
DigitalOcean is a bit friendler to small/medium business and individuals
you should feed your cat tuna

Personally I don’t think I want or need any cloud certs, I’m not going into devops or devsecops despite having experience in those feilds professionally. My professional experience will help.
As to why not general certs, it depends. I’ll grab some when I next go job hunting but I have over 4 years doing basically it all at my current job which will look wild on a resume
tuna
certs are expensive
I'm in love with WPF
that too and I have to pay out of pocket lol
especially lame with so many certs expiring after three years
comptia academy store is amazing for discounts
If I started a cert when I got my first IT job, it would have expired already
Yes def, So how did u land a job without a resume, I have 4 and i Can't land one lol
Yeah; I'd only recommend certs if you're looking to get another job or something.
good to know.
networking via people honestly
ya but every job require them
I was basically hired as help desk and rapidly rose to infosec (everything) and sysadmin
sadly my first job after school was help desk but it requred a computer science degree
for some reason
sad that it requires that
What were your qualifications when you landed your first job?
meanwhile it’s been my experience that CS grads are useless lol
Not all, but lately these days, I’ve heard others in CS degrees who stated that like half of their class struggled to even turn on their computers in the first lesson
Why is Paganini so good?
lol
Pagani or pagnini? Wth is paganini?
kids these days don’t have the benifit of groing up with computers, they grow up with tablets and phones instead, and have a warped sense of how tech works
A violinist
they r just in it for thr money or because their daddy told them 😂
tuna
I was lucky and got my first hand me downs around 9 years old
in the wonderful year 1999
just before the y2k scare
They were all older computers, but fixing them up and etc got me into this all
oh u started tech at 9?
I had a computer at home but didn’t know what to do with it cuz I thought windows XP is useless 🙃
I mean technically ealier, depending on how you count. 9 was just when I had “my own” computer to do anything I wanted with
Hot take: I liked XP
I don’t think that’s a hot take
It wasn’t bad
I also liked Vista 
a hot take but true is that Win 2K is the best Windows OS ever and it’s all been downhill since
it seems like dll's would randomly go missing with xp
What would you consider XP generation? 💀
Now we are falling out
ok boomer
Those who used XP obviously
my grandpa has a old windows xp or smtn i dont know
all i used to care was it had solitare
Vista is what pushed me to using Linux instead in the mid to late 00s
been there since, but I use every major OS on the daily
its a good thing i did though that's the only reason I have my job now
the cs degree was pointless lol
so you are the best and the worst admin there
boss randomly asks, “can you whip up a webserver who hosts three legacy web clients we have who are too cheap to move on?” Sure!
very simple docker compose stuff but I was happy with it and the clients didn’t know the difference
plus it obsolited an ancient Win 2008R2 box we had serving this stuff previously lol
lol
yeah they’re literally just static sites
Wasn’t too hard, but I had some previous experience with deploying Docker Compose statcks and stuff, so wasn’t too difficult to make my own
Nah they’re just really meh plain HTML, I don’t think a WYSIWYG editor was used or else the code would be way more ugly
I didn’t do much to the sites besides migrate them and update copyright notices and etc
i don't think i have ever seen a live site that was built by hand in html
with only html
You have I’m sure, you probably weren’t aware of it
well i mean the server
WYSIWYG editors kinda died in the 00s
and i work for a web host
Well CMS systems + CSS is an entirely different beast
Active directory? Boi im about to Actively Direct you to my cabinet and give you some tuna!
What even is that
“What you see is what you get”, basically like how MS Word shows you the formatting without markup, WYSIWYG web editors were the same way
and produced awful awful HTML
lol that’s because MS Frontpage and Dreamweaver have died
some people still try to use it
actually not sure if Dreamweaver is still alive but it would be better off dead if it isn’t already
there are no new versions
anyways, that’s my very brief devops experience if you can even call it that lol. But yeah I’ve got quite a bit of other Docker/Docker Compose experience under my belt
Im actually not sure why you need docker for flat html but I am used to control panels like plesk and cPanel
we’re just too small for k8s to make any sense
Because we needed virtual hosting, three domains, one host. There are other ways to do so, but this was a clean solution in my eyes
mhmm
Hello Hackers!
Hi @brave hinge
My friend is a data engineer with 2.9 years of exp. and he is planning to switch towards Security Analyst(SOC). Is this a right move for him. Because there are no openings at present for his current role in the job market?
the Nginix Proxy Manager just handles the virtual hosting requirements and forwards to the correct container. I’d recommend Traffik instead though if I were doing this now
I honestly don’t know what a data engineer rightfully does, but I don’t see any issues with moving to SOC, hopefully higher than level 1 but that would be just fine if they’re just getting into the infosec field
Is Data Engineering like PowerBI bs and etc? lol, usually that sorta thing has a fancier title so idk
Yeah search basically confirmed it’s like PowerBI stuff and similar
Yeah makes sense, one of our clients is going through an awful migration for their data which is not going well, but whew, they are letting us go so not our problem lol
turns out upending 20 years of legacy technology debt they blamed on us even though it was company internal is not easy. All of their DBAs and similar were always internal lol
Which company are you from
Me? I work at a Managed Service Provider so we’re the IT for dozens upon dozens of clients
Ohh noice
im so jelly beans
I am currently working as an intern at a startup as a soc lv1
Yeah it’s both great and has its downsides. When I was learning AD/GPO for the first time though, meant I had 12+ example domains to get aquatinted with and see real world examples of
@sinful moon His designation is software engineer with band U2. Is he doing a right move towards SOC?
I can’t rightfully say, but I mean, SOC gets a lot of data, and he is a data engineer lol.
if they have SIEM then he should do just fine if he adapts to the security focus
SIEM is very applicable to data engineering
oh “with the band U2” you don’t mean… lol
When I was working for an MSP it was a team of 4 (myself, the owner, and 2 others) managing 50+ small/medium companies. Boy some of the people calling in with their issues were not that pleasant to speak with.
My suggestion is like A.I is rapidly increasing and jobs are getting decreased. I suggested him to do a side hustle on SOC as cybersecurity jobs will be increasing and it's ever green.
Yep similar size although we’re only “slightly” larger than that
more on the order of 10-15 employees lol
Im just glad most of our customers are more technically proficient than most end users
when i worked on a help desk someone once called us cause the coffee maker wasnt' working
Eh, I wouldn’t worry about an AI run on our jobs, but sure, managed human SOC is a compliance requirement for so many regulations so has to happen indeed
we had a 5th guy who was hired in shortly after me however we had to let him go. Sadly the MSP no longer exists. I have a lot of appreciation for it and the coworkers I had
I lately had an issue with thm I purchased the 1 month premium membership and paid the required amt and still I am not able to access the premium rooms and material and also contacted the help support but ain't got any response donyou have any idea what should I do
Ah totally fair, ours has been running for over 20 years, of which I’ve only experienced about 4
@sinful moon I worked in finance on 20yo legacy code 😄 https://en.wikipedia.org/wiki/Software_brittleness
In computer programming and software engineering, software brittleness is the increased difficulty in fixing older software that may appear reliable, but instead, fails, when presented with unusual data or data that is altered in a seemingly minor way. The phrase is derived from analogies to brittleness in metalworking.
What ai will do is make 1 person do the job of 5
I’d recommend contacting THM support, which is support@tryhackme.com
Moderators here will not be able to remediate fully
I did that but ain't got any response
Keep in mind they operate on GMT/UTC time
how long ago did you contact them
Yesterday
Then let them address it today, again this is a UK company
Sure I saw will but one the sub told to join discord for instant help so I joined it today
If you don’t get anything by noon GMT/UTC time, then sure you could send a follow up
Yaaa
Totally fair, users or mods here can help you with tons of like tech support issues with the site, but billing and etc is beyond our control
Does this membership issue occurs always or is it just mee
idk why but running a vm on the chome seems way fun then on a nomal vm
I believe that is about how old this MSP was when I left
am i the only one?
It’s just you, I’ve had no issues with my premium account. But I can’t speak for everyone else lol
Noo I also have fun
Understandable
so u would chome one anytime?
Try ssh tunneling your HTTP(S) traffic to your local computer from your cloud VM and using Burp Suite as SOCKS proxy to send to Foxy Proxy in Firefox on your local. Now that is fun and awesome
I do the same to tunnel RDP traffic from THM to my local and it’s wild
erm minus the Burp and etc obvs
Was that English?
yes lol
Lol i don't know what u mean too technical
So I had a question I started cybersecurity a month back I have enough knowledge about the basics but it's theoretical so I would like some guidance
tl;dr I tunnel traffic I need from THM or HTB from my cloud VM to my local computer so I can view these resources… locally
my cloud VM is the one connected to THM via OpenVPN and this segments my exposure to THM/HTB entirely
compared to using a local VM
announcement soon I suspect 🙂
or in other words it’s babby’s first c2 lol
since I use this server basically as such being my attack machine
do i try to finish the cryptography unit today or do i just play hell let loose
I over specced it so I’m living with the nearly $20 a month cost, but realistically that’s not doing too bad. I could have just gotten away with a $5-10 expenditure instead, which helped when I was actually deploying this cloud VM provider at work
I do not actually need 2 cores and 4GB of RAM on my headless attack machine lol
1h 15m
yeah probably not
Just sounded neat and I didn’t know what I needed until I tried lol
i have a screenshot of that somewhere
are you staying up for the announcement?
na doctors appointment lmao
this guy
ah! 🙂
yea I've been up 18h
lol I’ve used Arch for 18 years but yeah totally fair
So I had a question I started cybersecurity a month back I have enough knowledge about the basics but it's theoretical so I would like some guidance
only regret for a pentesting server is postgresql admin for metasploit is a pain in the butt for rolling release
so I had to learn how to be DBA just to update that stuff… if I don’t just get fed up and wipe it out lol
finish the cryptography unit
First check your level then try some easy challenges which you think you can compete on your own
oh god
lol i can see that i just installed kali



